Data Processing Addendum
Effective Date: July 12, 2026
This Data Processing Addendum ("DPA") is entered into between SAAS for Healthcare LLC, operating under the Lablytics brand ("Lablytics," "we," "our," or "Processor") and the customer organization entering into an agreement for use of the Lablytics platform ("Customer," "you," or "Controller"). This DPA supplements and forms part of any applicable agreement between Customer and Lablytics governing use of the platform.
1. Purpose and Scope
The purpose of this DPA is to establish the responsibilities of each party regarding the processing and protection of Customer Data.
This DPA describes:
- The types of information processed.
- The purposes of processing.
- The responsibilities of each party.
- Security obligations.
- Data protection requirements.
- Processing limitations.
2. Definitions
"Customer Data"
Means information submitted to or processed through the Lablytics platform by or on behalf of Customer. Customer Data may include:
- Laboratory operational information.
- User account information.
- Workflow information.
- Documentation records.
- Inventory information.
- Training information.
- Other information configured by Customer.
"Personal Data"
Means information relating to an identified or identifiable individual as defined by applicable privacy laws.
"Processing"
Means any operation performed on information, including:
- Collection.
- Storage.
- Access.
- Organization.
- Retrieval.
- Use.
- Disclosure.
- Deletion.
"Subprocessor"
Means a third-party service provider engaged by Lablytics to process information in support of providing the platform.
3. Roles of the Parties
The parties acknowledge that Customer determines the purposes and requirements for processing Customer Data.
Lablytics processes Customer Data only:
- To provide the Lablytics platform.
- According to Customer instructions.
- As necessary to maintain security and reliability.
- As required by applicable law.
Customer remains responsible for determining:
- The legality of collecting information.
- The appropriateness of submitted information.
- Required notices and permissions.
- Compliance with applicable regulations.
4. Customer Instructions
Customer authorizes Lablytics to process Customer Data as necessary to provide platform services. Processing activities may include:
- Hosting information.
- Providing application functionality.
- Managing user accounts.
- Supporting workflows.
- Maintaining backups.
- Monitoring system reliability.
- Providing technical support.
- Improving platform security.
Lablytics will not use Customer Data for unrelated commercial purposes.
5. Customer Responsibilities
Customer is responsible for:
- Providing lawful instructions.
- Maintaining appropriate authorization.
- Managing user permissions.
- Ensuring information entered into the platform is appropriate.
- Maintaining compliance with applicable laws and regulations.
Customer is responsible for determining whether specific information should be entered into the Lablytics platform.
6. Lablytics Responsibilities
Lablytics agrees to:
- Process Customer Data according to applicable agreements.
- Maintain reasonable security safeguards.
- Protect Customer Data from unauthorized access.
- Maintain confidentiality obligations.
- Assist Customer with reasonable privacy-related requests where applicable.
7. Confidentiality
Lablytics will treat Customer Data as confidential information. Lablytics personnel with access to Customer Data are required to maintain confidentiality obligations.
Customer Data will not be disclosed except:
- To provide platform services.
- To authorized subprocessors.
- With Customer authorization.
- When legally required.
8. Security Measures
Lablytics maintains administrative, technical, and organizational safeguards designed to protect Customer Data. Security measures may include:
- Encryption protections.
- Access controls.
- Authentication mechanisms.
- Security monitoring.
- Backup procedures.
- Vulnerability management.
- Incident response procedures.
Security measures may evolve as technology and industry standards change.
9. Subprocessors
Customer authorizes Lablytics to engage subprocessors necessary to provide platform services. Subprocessors may provide services including:
- Cloud infrastructure.
- Hosting.
- Security services.
- Communication services.
- Monitoring services.
Lablytics requires subprocessors to maintain appropriate confidentiality and security obligations. Lablytics remains responsible for its subprocessors' processing activities to the extent required by applicable law.
10. Security Incident Notification
Lablytics maintains procedures designed to identify and respond to security incidents. Where required by applicable law or contractual obligation, Lablytics will notify Customer of confirmed security incidents affecting Customer Data.
Notifications may include:
- Description of the incident.
- Known impact.
- Remediation actions.
- Available information regarding affected data.
11. Data Retention and Deletion
Lablytics retains Customer Data only as necessary to provide services and satisfy applicable obligations.
Upon termination of services, Customer Data will be handled according to:
- Customer agreements.
- Applicable retention requirements.
- Backup procedures.
Where applicable, Customer may request deletion of Customer Data following termination.
12. Data Access Requests
If Lablytics receives a request from an individual regarding Customer Data that relates to Customer's responsibilities, Lablytics may direct the individual to Customer.
Lablytics may assist Customer with reasonable requests related to:
- Access.
- Correction.
- Deletion.
- Data handling inquiries.
13. Protected Health Information
If Customer uses Lablytics to process Protected Health Information ("PHI"), such processing may require execution of a separate Business Associate Agreement.
The parties acknowledge that:
- Customer determines whether information constitutes PHI.
- Customer determines whether submission of PHI is appropriate.
- HIPAA obligations, where applicable, are governed through applicable agreements.
14. Audits and Security Information
Upon reasonable request, Lablytics may provide information regarding security practices relevant to Customer's use of the platform.
Any audit or review must:
- Occur with reasonable notice.
- Avoid unnecessary disruption.
- Protect confidential information.
- Follow reasonable security procedures.
15. International Data Transfers
If Customer Data is transferred internationally, the parties will comply with applicable data protection requirements.
Additional contractual safeguards may apply depending on:
- Customer location.
- Applicable privacy laws.
- Nature of processed information.
16. Limitation of Processing
Lablytics will not:
- Sell Customer Data.
- Use Customer Data for unauthorized purposes.
- Disclose Customer Data except as permitted by agreement or law.
17. Changes to This DPA
Lablytics may update this DPA periodically to reflect:
- Changes in privacy laws.
- Changes in platform functionality.
- Changes in security practices.
- Changes in subprocessors.
Material changes affecting customer obligations may require appropriate notice or agreement.
18. Governing Agreement
This DPA supplements applicable agreements between Customer and Lablytics. If there is a conflict between this DPA and another agreement regarding data protection obligations, the applicable agreement will control according to its terms.
19. Contact Information
Questions regarding this DPA may be directed to:
SAAS for Healthcare LLC
Email: policies@lablytics.org